Vulnerabilities exploitable today
363,254in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,671
New KEV · 24H0
Exploit Today ≥ 701,610
Distribution · last window
- Critical2,901
- High12,392
- Medium7,637
- Low722
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-42518—12.6%
——4——CVE-2026-24594—12.6%
——4——CVE-2025-659457.5 HIG12.6%
——4auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditions. Applications are affected when they use the jws.createVerify() function for HMAC algorithms and use user-provided data from the JSON Web Signature protected header or payload in HMAC secret lookup routines, which can allow attackers to bypass signature verification. This issue has been patched in versions 3.2.3 and 4.0.1.27dCVE-2021-3038—12.6%
——4——CVE-2025-65681—12.6%
——4——CVE-2025-33251—12.6%
——4——CVE-2022-50771—12.6%
——4——CVE-2026-0710—12.6%
——4——CVE-2026-169686.5 MED12.6%
——4The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.15dCVE-2025-12182—12.6%
——4——CVE-2023-32155—12.6%
——4——CVE-2023-51744—12.6%
——4——CVE-2025-67500—12.6%
——4——CVE-2025-65186—12.6%
——4——CVE-2024-9343—12.6%
——4——CVE-2021-47195—12.6%
——4——CVE-2026-480268.7 HIG12.6%
——4lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write access to any repository branch can commit a `.md` object containing arbitrary HTML/JavaScript. Any other user who opens that object, or who navigates to a repository or directory containing a malicious `README.md`, executes the attacker-supplied script in their own authenticated session. lakeFS fixes the issue in v1.81.1 and lakeFS Enterprise fixes the issue in in v1.84.0. Enterprise customers using older versions can temporarily disable Markdown rendering by adding YAML to their config. No workaround exists for OSS release. Users are advised to upgrade to the latest version for both lakeFS and lakeFS-Enterprise.8dCVE-2026-189436.5 MED12.6%
——4The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low as subscriber to read arbitrary user, post and term metadata, including data belonging to administrators.8dCVE-2025-63740—12.6%
——4——CVE-2025-12341—12.6%
——4——CVE-2025-3433—12.6%
——4——CVE-2021-3429—12.6%
——4——CVE-2023-1677—12.6%
——4——CVE-2025-2475—12.6%
——4——CVE-2025-0358—12.6%
——4——CVE-2021-22152—12.6%
——4——CVE-2025-10198—12.6%
——4——CVE-2025-50019—12.6%
——4——CVE-2026-32385—12.6%
——4——CVE-2022-20493—12.6%
——4——CVE-2025-50022—12.6%
——4——CVE-2025-12520—12.6%
——4——CVE-2025-50013—12.6%
——4——CVE-2025-21170—12.6%
——4——CVE-2022-50826—12.6%
——4——CVE-2026-144259.6 CRI12.6%
——4Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)48dCVE-2025-48167—12.6%
——4——CVE-2026-58865.3 MED12.6%
——4Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)27dCVE-2024-500758.0 HIG12.6%
——4In the Linux kernel, the following vulnerability has been resolved:
xhci: tegra: fix checked USB2 port number
If USB virtualizatoin is enabled, USB2 ports are shared between all
Virtual Functions. The USB2 port number owned by an USB2 root hub in
a Virtual Function may be less than total USB2 phy number supported
by the Tegra XUSB controller.
Using total USB2 phy number as port number to check all PORTSC values
would cause invalid memory access.
[ 116.923438] Unable to handle kernel paging request at virtual address 006c622f7665642f
...
[ 117.213640] Call trace:
[ 117.216783] tegra_xusb_enter_elpg+0x23c/0x658
[ 117.222021] tegra_xusb_runtime_suspend+0x40/0x68
[ 117.227260] pm_generic_runtime_suspend+0x30/0x50
[ 117.232847] __rpm_callback+0x84/0x3c0
[ 117.237038] rpm_suspend+0x2dc/0x740
[ 117.241229] pm_runtime_work+0xa0/0xb8
[ 117.245769] process_scheduled_works+0x24c/0x478
[ 117.251007] worker_thread+0x23c/0x328
[ 117.255547] kthread+0x104/0x1b0
[ 117.259389] ret_from_fork+0x10/0x20
[ 117.263582] Code: 54000222 f9461ae8 f8747908 b4ffff48 (f9400100)16dCVE-2025-50014—12.6%
——4——